 |
Published by the Internet Security Alliance (ISA) and the American National Standards Institute (ANSI)
 Registration is required for new users.
|
The Financial Management of Cyber Risk introduces a new framework for managing and reducing the financial risk related to cyber attacks, which threaten businesses, national security, and the international community.
The 76-page document offers a pragmatic action plan that addresses cybersecurity from an enterprise-wide perspective. Developed by a task force of more than sixty industry and government experts, The Financial Management of Cyber Risk: An Implementation Framework for CFOs has been funded and managed by the private sector and is offered as a free resource on cyber risk mitigation for organizations across the country.
Applicable Standards, Frameworks and Guidance Documents
The following list of standards and reference documents is included in Chapter 4 Appendix of The Financial Management of Cyber Risk: An Implementation Guide for CFO’s.
Other useful reference standards, documents, and guidance include:
ISO/IEC 13335-1:2204
Information technology – Security techniques – Management of information and communications technology security – Part 1:Concepts and models for information and communications technology security management |
ISO/IEC 15408-1:2009
Information technology - Security techniques - Evaluation criteria for IT security - Part 1: Introduction and general model |
ISO/IEC 15408-2:2008
Information technology - Security techniques - Evaluation criteria for IT security - Part 2: Security functional requirements |
ISO/IEC 15408-3:2008
Information technology - Security techniques - Evaluation criteria for IT security - Part 3: Security assurance requirements |
The Financial Management of Cyber Risk is a publication of the
American
National Standards Institute (ANSI) and the Internet Security Alliance (ISA).
